CVE-2026-18482: Klarso GmbH Neo-Mjs

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools. Commit 88c77fc fixes these vulnerabilities.

Affected products

  • Klarso GmbH Neo-Mjs: before 88c77fc4 (fixed in 88c77fc4)

Published 2026-08-20. Last modified 2026-09-03.